CVE-2025-0763: Ultimate Classified Listings <= 1.7 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Update
The Ultimate Classified Listings plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the savecustomfields function in all versions up to, and including, 1.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change plugin custom fields.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0763?
CVE-2025-0763 has been classified as a medium severity vulnerability, allowing unauthorized data modification.
How do I fix CVE-2025-0763?
To fix CVE-2025-0763, update the Ultimate Classified Listings plugin to version 1.7 or later where the vulnerability is patched.
Who is affected by CVE-2025-0763?
CVE-2025-0763 affects all versions of the Ultimate Classified Listings plugin up to and including version 1.6.
What kind of attack vector is associated with CVE-2025-0763?
CVE-2025-0763 can be exploited by authenticated attackers with Subscriber privileges.
What functionality does CVE-2025-0763 expose to attackers?
CVE-2025-0763 allows attackers to modify custom field data due to a missing capability check.